Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Published Jun 12, 2026
2.3
LOWCVSS 4.0
EPSS 0.13%
Description
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_island/* endpoint accepts attacker-controlled props query/body parameters and renders any island component without verifying that the URL-resident hash (<Name>_<hashId>.json) was actually issued for those inputs by <NuxtIsland>. The hash is computed and embedded client-side but never validated server-side, so the same path can return materially different responses depending on the query. This issue has been patched in versions 3.21.6 and 4.4.6.
Affected products
-
- Version >= 3.1.0, < 3.21.6StatusaffectedConstraints-
- Version >= 4.0.0-alpha.1, < 4.4.6StatusaffectedConstraints-
- Version
- ≥ 3.1.0 · < 3.21.6
- ≥ 4.0.0 · < 4.4.5
- ≥ 3.20.0 · < 3.21.6
- ≥ 4.2.0 · < 4.4.6
No data.
No Red Hat product state for this CVE.
nuxt
npm
Introduced 3.1.0 Fixed 3.21.6nuxt
npm
Introduced 4.0.0-alpha.1 Fixed 4.4.6@nuxt/nitro-server
npm
Introduced 3.20.0 Fixed 3.21.6@nuxt/nitro-server
npm
Introduced 4.2.0 Fixed 4.4.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | nuxt | 3.1.0 | 3.21.6 |
| npm | nuxt | 4.0.0-alpha.1 | 4.4.6 |
| npm | @nuxt/nitro-server | 3.20.0 | 3.21.6 |
| npm | @nuxt/nitro-server | 4.2.0 | 4.4.6 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36418 Advisory
- https://github.com/advisories/GHSA-g8wj-3cr3-6w7v Advisory
- https://github.com/nuxt/nuxt/pull/35077 x_refsource_MISCIssue Tracking
- https://github.com/nuxt/nuxt/security/advisories/GHSA-g8wj-3cr3-6w7v x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-46342
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36418 | Advisory | |
| https://github.com/advisories/GHSA-g8wj-3cr3-6w7v | Advisory | |
| https://github.com/nuxt/nuxt/pull/35077 | x_refsource_MISCIssue Tracking | |
| https://github.com/nuxt/nuxt/security/advisories/GHSA-g8wj-3cr3-6w7v | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-46342 |
Change history (0)
No recorded changes yet.